Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-82331— Apache BuildStream: tar source extraction escape

Quick assessment

Affected
Apache Software Foundation Apache BuildStream
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Improper link resolution before file access ('link following') vulnerability in the source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, v

Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-82331

Vulnerability Information

Shenlong is analyzing...


Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache BuildStream: tar source extraction escape
Source: CVE Program / CVE List V5
Vulnerability Description
Improper link resolution before file access ('link following') vulnerability in the `tar` source plugin of Apache BuildStream running on Python < 3.12 allows malicious source tarballs to write files on the host, with the privileges of the user running BuildStream, via symlinks as part of source fetching. The impact of this issue is mitigated by: * BuildStream projects should only use trusted sources in their elements as otherwise the build output can also not be trusted * Tracking a source tarball pins its SHA256 hash, which prevents MITM attacks of users that are fetching an already tracked project * When running on Python >= 3.12, BuildStream >= 2.3.0 already makes use of the Python `tarfile` filter functionality, which blocks the symlink escape Users are recommended to upgrade to version 2.8.1, which fixes this issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
在文件访问前对链接解析不恰当(链接跟随)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache BuildStream 0 ~ 2.8.0 -

II. Public POCs for CVE-2026-82331

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-82331

登录查看更多情报信息。

Mailing List Discussions for CVE-2026-82331 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-23 · 25 CVEs total

CVE-2026-31377 7.5 HIGH Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service
CVE-2026-76183 Apache Tomcat: Bypass of security constraints for WebSocket endpoints
CVE-2026-73192 Apache Sling XSS: XSS possible through XSSAPI.getValidHref()
CVE-2026-92001 Apache Sling XSS: Missing parser resource limits
CVE-2026-91999 Apache Sling XSS: Improper escaping in the XSS Webconsole plugin
CVE-2026-91852 Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl
CVE-2026-96443 Apache Doris: JDBC driver URL validation bypass leads to remote code execution
CVE-2026-91928 Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf prote
CVE-2026-94251 Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape
CVE-2026-94243 Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence
CVE-2026-73581 Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate us
CVE-2026-75973 Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured
CVE-2026-86247 Apache Tomcat Native: Client certificate requirements can be down-graded
CVE-2026-77756 Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests
CVE-2026-77762 Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request
CVE-2026-77791 Apache Tomcat: DoS via busy wait during WebSocket close
CVE-2026-78383 Apache Tomcat: AJP DoS via missing request body
CVE-2026-78437 Apache Tomcat: HTTP/2 DoS via malformed request
CVE-2026-79677 Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout
CVE-2026-86248 Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with

Showing top 20 of 25 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-82331

No comments yet


Leave a comment